95479ebe77
Built and run for the first time in this shape. `pnpm install --frozen-lockfile` fetches the external data layer from Gitea inside the install stage and succeeds -- the step that refused an hour ago. Run with only the password and the base64 wallet set, and no path variable, the container serves 810 bytes at /shared-wallet.ngw with the same sha256 as the original file. The check that mattered most: the production bundle contains exactly one call to /festipod-config.json. That call being absent under NODE_ENV=production is what made the deployed application unable to sign anybody in, and its absence is invisible from outside -- the server answers, the page renders, the endpoint works, and nothing asks it anything. Two doctrine claims the build disproved, corrected rather than left standing: The `bun` peer shim the deployment notes describe as a live hazard does not appear at all in a built image -- `bun` is absent from node_modules/.bin and resolves to the base image's binary. The `onlyBuiltDependencies` approval is currently inert. Kept, since it costs nothing and the shape can return, but the paragraph now says dormant instead of describing a mechanism that is not running. Asset paths are emitted as `/../chunk-*.js`. Browsers normalise that at the root and the existing deployment already passes it through its proxy, so it works -- but a proxy that treats `..` segments differently would break asset loading, and the symptom would be a blank page with 404s on chunks, naming nothing.